CyberWiseCon Europe 2025

Robert Carson: Information Security Management Programs-Changing the Paradigm on Implementation...

40:22 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

In this session, Robert Carson discusses the challenges of implementing effective information security management programs within organizations. He shares his extensive experience in cybersecurity, noting that many companies struggle with insufficient budgets and resources. The speaker emphasizes the importance of decentralizing cybersecurity responsibilities through the creation of Business Information Security Officers (BISOs) in various departments. By distributing accountability across business units, organizations can more effectively manage risks and improve compliance. Carson also highlights the significance of integrating automation and appropriate governance models to enhance operational efficiency. Throughout the talk, he draws parallels between historical governance structures and modern organizational dynamics to advocate for a more flexible approach to security management.

Full transcript

ladies and Gentlemen please welcome our next speaker Robert Carson presenting the topic Information Security Management Programs changing the Paradigm on implementation and [Music] management all right so intro my background uh I was a m cor INF officer in a former life but basically last uh 12 years I've been putting in cyber security programs for companies I worked at as well as for other customers uh ISO sock

to Fed ramp all the fun things and worked with a lot of companies and seen a lot of uh challenges so part of this talk is just really just sharing Lessons Learned and things that I've seen go right and go wrong um because any advice I offer is probably because I screwed it up not because I'm some brilliant person and uh I'm the former CSO for Las

Vegas bide so if any of you ever come out to Vegas for Defcon or some hacker summer camp hit me up we'll have a beer um there you go and disclaimer hey what we're talking about you know got to do your own research what's best for you what works for a Sixers company may not work for a thousanders company so depending on your organization you need to

think about how you want to apply it stuff like that I'm happy to discuss afterwards about anything the other thing is if I talk about any name brand software it all sucks some sucks less than others I'm not endorsing any of it want to be clear um so because it's cool and so here's the challenge right for you know I guess from a the audience here and

it's hard to see with this light how many of you are in cyber security like running cyber security program security managers few of you okay cool uh do for those that raise your hands keep your hands up uh how many of you have all the budget you need you can put your hands down if you have all the budget you need okay oh yeah and all the

people where where do you actually work that sounds like a fantasy land um but that's the thing right for the most part most of us don't have the budget we don't have the time you don't ever have the resources you need so that's what we're going to kind of walk through like that's the challenge like how do we actually do things correctly and and how do we

integrate with the business how can you distribute that work because you're never going to have the staff that you need so what's my solution we got to break the governance model uh the origin the you know the whole we got to centrally control it inject yourself in every single process be part of everything we need to get rid of that like that's not working right it's it's

spreading you too thin you wind up bald looking like me right like you're gonna you're stressed out because you're just I got to be everywhere oh these people are idiots like that's not that's not going to scale right um so we got to Leverage moning the business is fruitless activi you're just chasing your tail and then know you guys ever heard the term of abiso so business

information security officer so think of that as Representatives or someone has that collateral Duty that extra Duty inside a different line of business so in Dev you might have an absec engineer right uh they handle the priority uh problems or issues for vulnerabilities inside of um Finance they help with the third party onboarding things like that or an HR in different lines of business you have people

that are actually paying attention to it so and here are some of the questions I hope we can answer you know how can we distribute accountability U of the program what can we do automate it and how do we stop wasting time all right so let's talk about reality um if you look at history any Empire that has lasted a couple thousand years they all had a

distributed model they had they had decentralized control the ancient Egyptians they used they had the Pharaoh but they also had uh their you know the Egyptian priests for lack of a better term that were out there and they're the ones that actually did the indiv the governing at the local level same with uh Macedonia uh Persian Empire name the Empire the ones that lasted uh that's how

that's how they worked really um you look at the former USSR uh they had centralized plan economy things like that didn't work out so well right some of you might might recognize that um you know and even with the US right like if you look at centralized control trying to control everything trying to control that fum doesn't work so well especially the further away you are from

the risk so you look at the Vietnam War the us there was a joke uh that you know guy couldn't even use the restroom without approval from Washington like when you have that type of centralized control it leads to poor effects so if you look at history we can tell that centralized control does not work very well but distributed model does that's where we want to push

that information out we want to give people autonomy to be able to work as they need is it really hot in here or is it me these lights are hot all right so let's talk about two hopeful cesos so there's let's let's talk about we'll talk about Rob and uh we'll call the other one Chris okay so Rob and Chris they both want to be cesos they're

at different organizations and they're their companies they make software they have a couple government regulations they got to put in ISO Saku fed ramp something like that uh maybe some gdpr whatever it is right you know this is Euro Euro crowd they've got to put those things in so what happens when when they start when the company starts is they insert themselves in every single process they're

part of third party risk management they're part of onboarding they're part of everything all change management meetings everything well what happens over time is they get spread thin they but they they become so Central to the company that you know it's like oh what we do without them like they scare everyone the fear uncertainty disorder like how do how do we do this well as time goes

on what's going to happen is that organization grows they start bringing in new people new people go hey this is not how it has to be they bring in the consultant the consultant we'll call that consultant Brad they come in and guess what happens Brad's gonna go you guys need to listen you need to distribute your stuff one guy's gonna hold on to his fom call that

again we'll go back to uh uh Sean and Rob Rob's gonna be smart Rob's gonna listen to the consultant and stop and let go of things that don't matter and that's that's kind of the point because what'll happen is the guy who holds on to everything and has to be part of everything gets burnt out and usually gets replaced that's what happens because they're so focused on

being part of every single thing that they can't get past themselves and realize they need to create these autonomous units provide that guidance get them where they need to be but they don't actually have to be part of everything you know and and I say this from somebody who's been guilty of it I've done it myself so and why why should we not be part of every

single thing you're not the risk owner at the end of the day the risk owner needs to sign off on the risk why are you trying to worry about something that's not your problem if they don't care you don't care be honest so we got to distribute that risk we got to understand the accountability is a big piece of that it's not your make the business units

accountable and if they're not doing it then they're not doing it and that's the result on them it's not on you provide the guidance provide that process make sure it's effective itive and efficient and they understand it but you don't necessarily have to be a part of everything stop trying to control what you can't all right I got a lot of memes in here by the way

so I don't know if they work with the Lithuanian audience all right so let's talk about a better way so where can we integrate well HR is easy so background checks think about that you join an organization and uh if you want a copy of this afterwards just hit me up on email sent it to you um background checks it's easy right A lot of times HR

handles that anyhow they do the screening to make sure that stuff happens Finance and Accounting so what if you had a process in place where unless it was uh let's call it a level three software or some very specific type of data and they didn't have the right certifications that SAS that that software you're buying didn't wasn't very secure that's the only time you're involved otherwise the

organization wants to do it they fill out the questionnaire they do the risk assessment themselves and then all Finance does is make sure that it's uh it was done do you have to be a part of it if they did that stuff right if they actually know what they're doing if you train them if you have that biso who has a little bit of training understand what's

going on they can they can do that risk assessment for you you don't have to be a part of it get yourself out of that process because now you're not the one stopping the company from buying things you're out of that process you're not you're not slowing anybody down sdlc will talk about that in a little more detail and there's people here at this conference that are

going to be that are probably pretty amazing at it and then legal right contractual requirements we've got to make sure that we're covering those things but you know what I used to is I'd provide legal here's a list of stuff we can agree to and if we if it's something different Call Me Right get yourself out of the process provide the guidance provide structure for people to

execute but you single process because you don't scale let the business be autonomous let's get out of the way of ourselves so how do we structure that stuff right so Distributing your team instead of having a big cyber security team what if you just help write job descriptions for different departments that included a a business information security officer or that that Duty so your your appsec engineer

they sit under the there maybe on this uh site reliability team same kind of thing and the cso's over to the side helping out any questions so far or debate this is a lively audience let's let's get excited what you got big man there absolutely are so uh I've heard this term since 20 2013 or so I know they had it at City bank and then uh

there's a Netflix documentary where the C so for Netflix talks about it as well no no so you still have actually can I get that pointer thing that you offered me that I told you I didn't need maybe it's oh never never mind I don't have uh that's fine um so what I have over here is ciso is over there but they're not part of that Chain

of Command right this is an autonomous unit so the ciso is there they're providing that guidance they're maybe meeting with the BOS on a monthly basis making sure the processes are functioning they know what's going on so the ceso still has a role but instead of having a massive team maybe you have one senior security analyst and a internal auditor but all those other duties that we

the security team do that are burnt out trying to do everything they're pushed to the actual business so question though all right any other questions while we're going here like to slow myself down for a second or I'll just keep rambling all right so distribute that team you got to recruit for your team right I don't know if anyone's even old enough to recognize that movie um

but uh you got to recruit right you got to help be part of those organizations their hiring process looking for somebody that's the ABC engineer right or who's someone who's who's a nerd who wants to go to Defcon maybe that's part of their their uh package they go with you to hacker summer camp every year or they go to cyber wisec con this conference right here right

they go to something they get some extra training they're part of it so they can be part of that process and you can find somebody from HR from Finance from accounting like doesn't always you know the app set guys it's pretty easy um sometimes getting them to leave their basement is a little bit hard but you know I don't know if you have that in Lithuania but

in America most of our Engineers live with their mom's basement but maybe not here um so recruit put in those BOS right like having those Representatives inside those departments they can run that process for you they have they have a day job and part of their day job is to do that but they they're coding or or they're Consulting but they also make sure that process functions

inside of there so you're Distributing that model out and you're not trying you're not in the way of them doing things and then you use that internal auditor to check on things so and I have a talk tomorrow where I get a lot more into gorilla Warfare um talking about Insurgent tactics but if you look at gorilla Warfare and distributed models right that's what gorilla Warfare is

distributed uh tactics where people are operating at small unit level you get the political Wing that's essentially your B okay and the military Wing that's your senior security analyst and your internal audit so those are functions that maybe you are keeping underneath your security team but you're pushing that b so out they got a dotted line to you where you can talk to them and and educate

them but they're part of that business process that's already functioning in this way you're not in the way you're not stopping you're not the CI no right because we all have been guilty no one wants that title this is how we get around so that's my time check I want to get in trouble all right cool all right so third party management sass application so here's here's

one way to look at it right so you've got there's tools out there there's uh SAS security posture management there's Cloud security posture management there's all sorts of tools but the idea whether it's a tool or it's an actual just a system here's how you can do it right the system owner they're responsible for it they give you the stuff you set it up in the system

but the alerts go to the biso and then they're handled by the system owner so if they're not doing their access reviews or their access is inappropriate it doesn't even touch you it just goes straight to the system owner and make them accountable for what's going on why do you have to be chasing them down is that really Your Role or is your role to make sure

they're educated and make the best decision they can because at the end of day you know you can you can cry all you want say what you want but the business is going to win so let the business prioritize and it's their choice because otherwise a lot of times what happens is you're almost putting yourself as becoming the scapegoat where you feel that responsibility like man well

if we get hacked I'm in trouble like it's going to be my fault no no it's not it's not going to be your fault because you're not accountable for doing this you alerted them you made sure the process was in place it was functional they have a responsibility and let's put that responsibility back on them same thing Cloud security posture management those tools work great I'm not

recommending anyone in particular they uh they work for what they're what they're good for but again putting that stuff in place what tools can use we're going to talk about GRC tools for a second here as well this one's near and dear to my heart but these are things that like um you can validate the compliant requirement without actually uh we don't have to pull unique evidence

you don't have to go to these different to to it stuff like that like how do we get this information into our systems so what in the world ah okay sorry I thought my someone edited my slide all right what are GRC tools good for so what I do for living obviously L is is the Arts and Crafts of cyber security so I deal with JC tools

all the time and the marketing around them is amazing they will tell you that they're going to help you grow hair help you get girls I'm going to lose weight it's going to be awesome they don't do all that but they are good for are these things and one of the first things I would look at if I have a GRC tool is I'm looking for a

two-way connection into Dev or into any ticketing systems that the other parts of the business use because they're not going to go into your GRC tool to do anything the other parts of the business aren't what you want is you want to be able to create something where it creates the ticket in their queue in the system they already use that's a big piece so these are

ways to do it they're good for collecting evidence I had a customer who hired us to help them with ISO and they were working on sock 2 I don't know if you guys are familiar with that one it's more of a US regulation uh they said they're going to do sock 2 on their own they use the magical GRC tool they passed ISO no problem they failed

sock too which they shouldn't have but they did because they believed in the magical hype so remember when you get these tools you still have to run the program you still have to do things the other thing is is making sure you define the process you shouldn't be buying tools that tell you how you're going to do it you should be able to have there should be

enough customizability custom ability whatever that word is to be able to uh figure out what the what the actual best way to do is and they great for evidence collection but the other part is like what if you're collecting the evidence before you go out there and start collecting all this evidence you're you're pushing out your biso you're doing your Paradigm Shift you're going okay I'm just

gonna do this stuff how are you going to act on it right if you're just collecting evidence to know your program is a failure you know maybe that's not the best prioritization let's prioritize the evidence where we can act on it like figure out what you're going to do when something goes wrong that's the other piece I see that a lot of cyber Security Programs uh start

they start with they focus on the controls right they are sitting this is so much better over here we should move that stand gez um they focus on the controls but they don't they forget about the framework so when you roll out a process you need to think about how are you actually going to what are you going to do to audit it how are you going

to check on it what is the efficacy of that process what are your metrics around it as opposed to just sitting there and rolling out controls right because you need to have a plan to deal with the actual when it breaks because it's going to right is it education is it retraining are we going to automate something what are we going to do but having that process

in place before you roll out actual controls is a lot more important that's why personally I'm a big fan of iso 2701 because it gives you a better framework on how to run a program as opposed to some of the more control based uh standards all right any questions so far anything else man it's a lively group you guys sure you're not from Wisconsin like in the

US is that oh look at that where do you get budget oh this is sweet where do you get budget for BOS so you don't so the way that works is they're already either you were going to hire an absc person or you're Dev is going to hire another developer it's just part of that that person's collateral Duty so you work with Dev and the and the

and Leadership to make that part of their job description does that make sense and can you suggest concrete Enterprise grc's besides logic gate yeah Enterprise level so I I'm a fan of hyperproof uh hyperproof is more customizable does a lot of allows you to create that program based on what the actual organization does um are what's it called what's that big one that like you need like

three admins to um what's that no no no no it's worse than that man way worse uh like it'll come to me but I guess well I wish if that Anonymous person could tell me what size what they mean by Enterprise because like that's a whole joke are you talking 30,000 people or a thousand people like small Enterprise large Enterprise publicly traded um but yeah I like

hyperproof uh I've used da v um dra's fine uh but it's with the problem I have is that I like programs that allow me to make sure that we are tailoring our processes around what the company actually does and not making our processes tailored to what the technology will allow if that makes sense um and with hyperproof I get at least when I work with our customers

I get more uh get like five Frameworks because most customers have to deal with more than one standard and so you need to be able to measure how you're running one program with multiple Frameworks right because most of the time you're not dealing with just sock 2 or ISO 270001 you've got gdpr you've got Hippa you've got PCI you've got whatever it is I'm sure there's a

Lithuanian one I don't know what it's called but sure there's something it's coming you know um so you need to have one that lets you do multiple Frameworks but yeah it's a good question though what I don't like about uh some of the tools is you can't use them let's say your password policy is 12 characters and you change it every 62 days okay I'm not here

to judge as long as you got MFA I really don't care what your passport policy is to be honest but uh you should be able to have the the technology alert on the software or systems that are not set up to meet what your passport policy is not have to change the systems to meet what the GRC tools says your password policy should be because a lot

of times you kind of either you have to wind up turning it otherwise all right should BOS have the same technical qualifications as the ciso no this the BOS should be good at what they're actually good at so like your B that that's working in depth right they should be good at code they should maybe go some secure code training like we we did uh at um

a company my my business partner where we worked together uh we taught a secure coding class and then we found a few developers that were actually using it and they were using the free version of burp Suite what did we do we went and bought them the full we used our budget to go buy them the full version of burp site we opened up the um what

was it we use tenable nessus the scanning solution and we open that up to them so they could run all the scans they wanted and check it and verify it and make sure it was remediated so that we empowered them to just get stuff done they weren't waiting on us at all they were able to operate much more effectively you know and the way one way if

let's say Dev doesn't want to cooperate one way to do that is just let start letting your customers pentest you all of a sudden they'll want to work with you on the front endend as opposed to dealing with that customer at the end uh when you have the vulnerability it's it's much harder to fix um yeah and that's DLC right so that all the questions we got

for right now Perfect all right uh so system owner you're responsible for ensuring the testing Security advis on the risk test the efficacy through third party web app so you you Empower that process and you still use your Audits and things to make sure that the process is effective you know if you were looking at you know third party SAS you know third party software and and

services that the company's procuring you do your Audits and validate are we following the process correctly but it makes sure that marketing when they're hiring somebody to do graphic design some contractor you're not wasting time with something that doesn't really matter like who cares right whereas like if it's something super important it's got the customer's critical data and it absolutely then you want to you want to

make sure that they're doing more due diligence there right not every you're not guarding nuclear codes so or at least not everybody in the organization is so making sure the risk makes sense implementing that process right so I know there's a lot of devops talks this is from a compliance perspective because you know we're the new sexy just don't tell them everybody but this process right here

you're doing the V doing the vulnerabilities all of this can be completely automated you don't have to do change meetings you don't have to do peer review and you can still be compliant change management does not mean change meeting it's a fun fact right if you've got secure coding like a sonar Cube or a ver code something like that that's actually integrated in the pipeline and it

and they're not allowed to override it hey or if they want to prove it's a false positive at least then it requires peer review you can run this they can run this stuff all day long as long as the environments are built correctly and they can test test and go through and they're following change management you're managing the risks because you're using automated checking right there's no

rule that says you have to physically go check something or another person has to for everything that's something that is made up any questions on that I like that picture all right I don't know why I'm holding none of this thing I think it's yeah what's up man yeah I have believe it or not it's kind of like a unicorn but I have seen it like would

I say it's uh as elegant as the picture no because the biggest challenge is in the dynamic app uh baselines for automation so when you're when you're doing the testing making sure you have the right test environments built and as the as the app starts to add more features you have to you have to continue to add to that piece that's that's where the challenge is right

but at least you're not talking to developers about their MacBooks or something stupid you're talking to about good Cod right and they are more paranoid than we are so if we can help the developers be less paranoid be in their own little space you know hanging out in their hoodie their mom's basement dark lights you know let's let's let them do this that but yeah I would

say that's one of the challenges the other challenge is privacy by Design but if you can be there on the front end as a guiding Guiding Light to help them understand what they need to think about it's great like I remember I got a question from a development team and they're like uh is there a reason why I can't just put your password's wrong or your username

is wrong why do I have to say it's it's one of these two and it's explaining to them well if you got the password you know helping them understand like we don't want to give too much away here's why it's set up that way like that's where you can play a role that's a good question though any any else does that um all right I'm going through

my list here of things yeah but it I have seen it actually work for real it's uh the getting and here's what I would tell you when you're trying to put this in trying to get a 10% functional system is better than no function so you have to continue to take the 10% wins and continue to improve on it on a regular basis usually more at the

smaller organization because we're able to start it right it's sometimes it's harder when you come into the big organization they're going from like a waterfall methodology where they have releases to a devops model and it's the challenge when you get with the small organization though is that they're usually doing Lord of the Flies just doing whatever they want and calling it devops which is the other negative

side right you have to explain them like that's not what devops actually is you can't just do what you want right um but yeah see I've seen it it's uh it usually takes very strong Dev leadership that understands what's going on to get it pushed down and force people to actually do it it's not going to be security it's going to be uh it's going to be

your Dev leadership yeah change management doesn't mean meeting uh and we want to record the evidence so from a compliance and security standpoint we want to check to make sure they're doing the right stuff we want to automate those tests right so static code analysis Dynamic code analysis you know continuous pen testing that you know unit user code all those different tests you can do it the

other piece too that I think uh people do screw up when they start doing this automated testing is a a lot of the tools will hold 60 90 days of logs but for a security program you generally need 6 months to a year of logs so making sure as you're putting the stuff in that you're actually logging stuff for the proper duration if you going for a

sock 2 type 2 and you're in your second year they're going to go for a whole year of monitoring so you need to have a year of evidence so you got to make sure that you're you're thinking through that as you're putting in some of the automation Nick stop new stupid yeah yeah so and this is the piece where like you really do get ahead of things

um having them understand on the front end what's going on privacy by Design security by Design that's a big piece so you're trying to prevent net new stupid you can't fix the past we're trying to stop future stupid problems from occurring what are these benefits there you go plus we got a cat on a unicorn wouldn't be a problem proper security conference without a cat mem let's

be honest there we go least somebody's laughing like come on like guys like the Frozen chosen all right in evidence right hey same thing uh make sure you collect that evidence but if you have the log stuff you shouldn't have to go to them that's where the GRC tools do play a role uh getting those connectors having them plugg into your sim so you don't have to

bother people and then again change management and if you're on the it side you still don't have to I went I was at a company where we had to do two change meetings it is a two review change process it was awful and 75% of the things we discussed did not need to be discussed so what you can do is you can have setup where like hey

the change goes out goes into slack whatever people have three days to respond and uh essentially if someone wants to have a meeting you can but this way you're not having meetings unless they're actually needed it'll help speed up that process too on the it side especially when you have more stakeholders involved and you need uh a little bit different buyin than maybe a devops model something

like that where you're making organizational change you're roll out mobile device management or some other terrible tool that's going to lock out your executive team um things like that all right other tips and tricks so do an operational management looking at business initiatives you know it governance I don't know uh I don't know how much they actually help but if I know what the business is doing

I can be far more aligned with what's going on Doc procedures draw a treasure map words are hard no one knows how to read anymore all right so draw a Candy Land map or your favorite Shoots and Ladders map and have them figure out how to get to the Little Treasure and they can follow the picture it's way easier all right screenshots in a Wiki I have

slapped a GoPro to an engineer's head before I have no problem doing that the other alternative is have them turn on zoom and press record you need to make work instructions or some or some kind of documented procedure just make a video library everyone watches YouTube make your own internal YouTube Library there's no rule that says it all has to be written in some Word document you

can do it in a PowerPoint I don't care but make it easy for yourself right what you got yes that's not true anymore so you turn on that AI thing and zoom boom what you got yeah you like that now it would be a lot faster right just think about because the other part too is you want people to be able to update stuff because when the

stuff does hit the fan you need to be able to you know look at it figure out what you're supposed to be doing or somebody's out so if you just turn on Zoom turn on the AI helper or whatever you're going to have the searchable text right and you're going to have um it's way faster to update because I mean dude I don't know if you guys

I mean I've been in Microsoft where they change where the button is while I'm in there like I think it's here and then now it's it's over in the security compliance now it's in compliance now it's over here I don't know like trying to find it the other part too you know there's all this don't click this training I like make your own adventure I think that's

more fun than static tabletop stuff like that uh you know helping the organization understand if we don't do our backup tests this is what might happen and like if You' and if you've done your backup test you can pick a if you can't pick B if you want to see an example I can show you guys later you know running a GRC tool I think is better

thing manual pen test automated pen test there's nothing wrong with doing automated pen testing a lot of network tests and a lot of pen testers you know on the back in they just have a bunch of scripts they're running there is a part where there is a manual test where that's very important of exploitability of of like how do we put this all together but until you're

actually ready for it maybe maybe you spend your money elsewhere in the in the beginning and then uh controls based on the prescribed risk so I was obviously US military we had secret and then we have top secret and there's rules for secret information and there's rules for top secret information writing your program and implementing your program where you're using those rules so they're appropriate so that

way you're not trying to guard things that matter few more thoughts I don't know if anyone will even get these jokes does anyone get this you might sock too this might be wasted on this audience I don't know in search of a life come on ISO like man rough crowd but the other part though because I know this guy speaks Kling on uh being an expert in

any these standards that's great the go your business doesn't care but you do need to be able to talk about Market opportunities things like that they want to sell to the US government okay we got to talk about fed ramp we got to talk about nist you want to sell a European market we got to talk gdpr but you got to be able to help the the

business grow right and angry rant don't buy any more tools unless you have service or headcount to support it we just buying more tools cuz it's uh if you want if you want minimum viable compliance just buy a dumb tool and use their audit partner you'll get pasted uh and when you're helping when companies are trying to put in a process any process is better than no

process and Lord of the Flies so it's fun to chase people around and uh there you go in summary let's break that governance model let's not try to control everything ourselves let's try to push that down let's use BOS Let Them Be A Champion stuff like that and in closing I do have a podcast I would love to have any of you on it you're welcome to

sign up uh it's a 10-minute podcast you just tell me a cool story about something that actually worked not just stuff that failed because I got plenty of stories out there that didn't work I want to hear stories that actually succeeded it's a chance for you to get yourself your own little LinkedIn 10-minute commercial about how awesome you are and we get to spread some love about

from the security standpoint of like good things because let's be honest I don't think anyone sent this guy an email saying thanks for having email work all day you know if you gotten a text message saying hey thanks I didn't get ransomware today I really appreciate it no probably not so this is our opportunity I don't know I will have to go talk to my people as

soon as this is over thank secure H all right any other questions we got here any recommendations for continuous software dependency known well that's a it's a lot of words um continuous software dependency so you're talking about like uh uh sonar Cube or not sonar Cube but tenable tenable nessus like that type of vulnerability or are you talking like code CI pipeline I guess would be the

question so if you're talking bigger picture I'm a big fan of uh tenable nessus the cloud ver Cloud version because they actually will allow you to reclassify things and only for a certain period of time so you can actually document what you're doing you're what you're and also move things up because sometimes two mediums equal a high uh otherwise you know ver codee's the best but ver

code is very very in-depth and if it doesn't work with your pipeline it may not be the best tool um so when our Cube works there's plenty of them out there I'm sure they've got all sorts of cool names these days any other questions is that it any else from the audience all right thank you all for your time